First published: Thu Jan 22 2009(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. NOTE: some sources list the id parameter as being affected, but this is probably incorrect based on the original disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MODx CMS Evolution | =0.9.2.1 | |
MODx CMS Evolution | =0.9.0 | |
MODx CMS Evolution | =0.9.6 | |
MODx CMS Evolution | =0.9.1 | |
MODx CMS Evolution | <=0.9.6.2 | |
MODx CMS Evolution | =0.9.6.1 | |
MODx CMS Evolution | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5939 has a medium severity level due to its ability to allow remote attackers to inject scripts.
To fix CVE-2008-5939, upgrade to MODx CMS version 0.9.6.3 or later.
CVE-2008-5939 affects MODx CMS versions 0.9.2.1 and earlier, including 0.9.6.2.
CVE-2008-5939 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2008-5939 can be exploited by attackers without needing authentication.